
Came across a really interesting BYOVD chain recently The loader transitions execution from user mode to kernel mode without triggering UAC, downloads ntkrnlmp.pdb from Microsoft’s symbol server, decrypts the AMD PDFWKRNL.sys driver vulnerable to CVE-2023-20598, and zeroes kernel callbacks associated with 20 security drivers across seven vendors. This blinds EDR products before the loader deploys what we are tracking as a new information-stealing malware family called Lunex, targeting the CIS region. Final payload after BYOVD blinds EDR: psychedeliclove.exe, full C2 agent. 7 browsers, 6 wallets, Chrome/Edge NMH persistence via com.lunex.explorer. Triple persistence. Live C2 panel at time of analysis. I have been unable to find any documented technical analysis of the binary. However, I discovered that @btcoolteam conducted OSINT research into the Lunex panels in June, which appears to be related. I will be publishing a blog with a more detailed analysis soon. IOCs: hxxp[://]107[.]175[.]82[.]242[:]9000/wilow/psychedeliclove[.]exe hxxp[://]193[.]178[.]159[.]128[:]8080 uasputnik[.]com Loader: bf14cd6c3328ebd08e940478b5d1da04e9e5aa576d045d41950bf4f1e2456dd8 Driver: 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1 Stealer: 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90 #malware #BYOVD #threatintel
